Public Key Credential Enrollment for Interoperable Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems rely on proprietary formats that create interoperability issues, requiring multiple credentials for different locations and resources, leading to inconvenience, increased administrative burden, and reduced flexibility, with potential security risks due to misplacement and vendor lock-in.

Innovation Solution

Implementing a Public Key Access Control (PKAAC) system that enables devices to generate PKI key pairs, with the public key serving as a credential, allowing for secure authentication and enrollment through a user's device, facilitating interoperability and user-friendly 'Bring Your Own Credential' (BYOC) access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If proprietary access control credentials are used for different buildings and locations, then access control security is provided, but interoperability is limited and multiple credentials are required

Engineering Contradiction:
ImproveinteroperabilityVSAvoidnumber of credentials
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal credential system where a single cryptographic credential can be used across multiple access control systems and locations. The credential is designed to be location-agnostic and system-agnostic, allowing users to access different buildings, floors, and resources with one credential rather than multiple proprietary credentials.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces a credential as an intermediary between the user and access control systems. This credential acts as a universal mediator that can be recognized by multiple access control readers across different locations and systems, eliminating the need for multiple location-specific credentials.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple access control credentials are required for different locations, then access security is maintained, but user convenience decreases and administrative burden increases

Engineering Contradiction:
Improveaccess securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The credential is designed to provide universal access across multiple locations and systems while maintaining security. A single credential replaces multiple location-specific credentials, making the system easier to operate while preserving security through cryptographic verification at each access point.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables users to self-enroll and self-manage their credentials without requiring administrative intervention for each new location or access point. Users can independently provision their own credentials that work across the entire system.

Inventive Principle:
Principle #25Self-service

3Ease of manufacture

If proprietary credential formats are used, then access control functionality is provided, but vendor lock-in occurs and flexibility is reduced

Engineering Contradiction:
Improveaccess control functionalityVSAvoidsystem flexibility
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The credential system is designed to be vendor-agnostic and system-agnostic, providing access control functionality across multiple platforms and locations without being tied to a specific vendor's proprietary format. This enables flexibility and prevents vendor lock-in while maintaining full access control functionality.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system uses cryptographic parameters and formats that are standardized and vendor-neutral, allowing the same credential to work across different access control systems from different vendors. This changes the parameter space from proprietary formats to universal cryptographic formats.

Inventive Principle:
Principle #35Parameter changes

4Ease of operation

If traditional access control systems are used, then access management is provided, but security risks increase due to credential misplacement and centralized vulnerability

Engineering Contradiction:
Improveaccess managementVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system segments the credential into cryptographic components distributed between the user device and the access control system. The private key remains on the user device while the public key is stored in the credential, eliminating the security risks associated with centralized credential storage and physical credential misplacement.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system replaces physical credential mechanisms (cards, tokens, badges) with a cryptographic digital credential system. This substitution eliminates security risks associated with physical credential misplacement, loss, or theft, while maintaining ease of access management through digital verification.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP4614469A1Enrollment of a public key for use as a physical or logical credential
Publication Date: 2025.09.10 TYCO FIRE & SECURITY GMBH
  • EP4614469A1 patent drawingFigure 1
  • EP4614469A1 patent drawingFigure 2
  • EP4614469A1 patent drawingFigure 3

AI summary

Example aspects include techniques for enrollment of a public key for use as a physical or logical credential. These techniques may include receiving, at a first PKAAC access control reader with enrollment capabilities, a PKAAC authentication request from a PKAAC-enabled client application of a client device, and determining that the PKAAC authentication request corresponds to an identity that is unenrolled. In addition, the techniques may include collecting pre-enrollment information in response to the PKAAC authentication request corresponding to the identity that is unenrolled, and generating enrollment information based upon the pre-enrollment information, the enrollment information including authorization information indicating that the identity is authorized to access an access point. Further, the techniques may include providing, via a second PKAAC access control reader, access to the access point based on the authorization information.